Node.js Patches Memory Leak and Permission Bypasses
ID: e60bba6a-d9bc-5950-aeaf-f1a645944759
STIX ID: report--e60bba6a-d9bc-5950-aeaf-f1a645944759
Feed Name: securityonline.info
Node.js published critical security updates across active release lines (25.x, 24.x, 22.x, 20.x) fixing eight vulnerabilities (three high, four medium, one low). The most serious, CVE-2025-55131, is a memory allocation/race condition that can leave buffers containing leftover data and potentially leak in-process secrets (tokens/passwords), especially when using the vm module with timeouts; two other flaws allow permission-model bypasses via crafted symlink paths and Unix Domain Sockets. The release also addresses multiple DoS crash vectors; developers are urged to upgrade to the patched versions to prevent data leaks and service disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
